Skip to content

Instant download after payment

Privacy Policy

What we collect, why we collect it, who else handles it, and what you can ask us to do with it. Last updated 28 August 2026.

What we collect

  • Account details — your name, email address and, if you choose to give one, a phone number. Passwords are stored only as a bcrypt hash and cannot be read back by us or by anyone else.
  • Order details — the products you bought, the price, the currency, the name and email you gave at checkout, any note you added, and the outcome of the payment. No delivery address is collected, because nothing is posted to you.
  • Payment references — the payment provider’s own identifiers for the transaction and for you as their customer, plus the card brand and last four digits so you can recognise the payment. We never receive or store a full card number.
  • Download records — which files your account has access to, how many times each has been downloaded and when it was last downloaded. This is what makes the download work and how misuse is spotted.
  • Content you write — reviews, wishlist items and the contents of your basket.
  • Email records — a log of the transactional emails we sent you and whether sending succeeded.
  • Cookies — a sign-in session cookie, a basket cookie so your bag survives a refresh, and a cookie holding an applied discount code. All are strictly necessary for the shop to function.

What we do not do

There is no third-party analytics, advertising or tracking script on this site. We do not profile you, we do not build an advertising audience, and we do not sell or rent personal data to anyone.

We do not currently send marketing email. If that changes, it will be opt-in and this policy will be updated first.

Why we use it

To create and secure your account, to take payment, to give you access to the files you bought, to send the transactional email that goes with an order — confirmation, verification, password reset — and to answer you when you get in touch.

Order and payment records are also kept because we are required to keep records of sales.

Who else handles your data

Only the services needed to run the shop:

  • Paddle — payments. Paddle is the merchant of record for your purchase, which means it is the seller on the transaction and handles the card details, the tax and the refund. It has its own privacy policy, and your card data is given to Paddle, never to us.
  • Resend — sends transactional email on our behalf.
  • Cloudinary — stores product images and the purchasable files themselves. Purchased files are stored privately and reached only through a link that expires within minutes.
  • Our hosting and database providers — which store the data described above.

The specific hosting and database providers, and the countries your data is stored in, need to be named here by the business owner before this policy is complete.

How long we keep it

Order, payment and refund records are kept for as long as tax and accounting rules require — including for orders that were refunded, because deleting the record of a refund would remove the evidence that it happened.

Account data is kept until you ask us to close your account. Verification and password-reset tokens are short-lived and expire on their own. Basket and discount cookies expire within thirty days.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to close your account and delete it. Email hello@meemiart.com and we will respond within thirty days.

Closing your account ends your access to files you bought, so download anything you want to keep first. Where we are required to retain a sales record, that record is kept even after an account is closed.

Depending on where you live you may have further rights, and a right to complain to a supervisory authority. Which authority applies depends on where the business is established — see the notice at the top of this page.

Security

Traffic is served over HTTPS. Passwords are hashed with bcrypt. Purchased files are stored privately and are only ever served through a short-lived signed link, after we have checked that your signed-in account actually paid for that product. Payment confirmations are accepted only when they carry a valid cryptographic signature from the payment provider.

Access to order and customer data is restricted to administrator accounts, and that check is re-run on every request rather than trusted from a previous one.

Contact

Questions about this policy, or about your data, go to hello@meemiart.com or through the contact page.